---
layout: docs
page_title: Vault UI
description: Interact with Vault using the UI.
---

# Vault UI

Vault features a web-based user interface (UI) that enables you to unseal,
authenticate, manage policies and secrets engines.

## Server configuration

To activate the UI, define the [`ui` stanza](/vault/docs/configuration/ui)
option in the Vault server configuration. The UI runs on the same port as the
Vault listener. As such, you must configure at least one `listener` stanza in
order to access the UI.

For example, the following configuration block enables the UI at
`https://10.0.1.35:8200/ui` for any machine on the same subnet as long as there
are no network firewalls in place that explicitly block communication:

<CodeBlockConfig hideClipboard>

```hcl
ui = true
listener "tcp" {
  address = "10.0.1.35:8200"
  # If bound to localhost, the Vault UI is only
  # accessible from the local machine!
  # address = "127.0.0.1:8200"
}
# ...
```

</CodeBlockConfig>

The Vault UI is also accessible at any DNS entry that resolves to the configured
IP address. For example, if you use Consul, you could configure a Consul service
address for the Vault UI as `https://vault.service.consul:8200/ui`.

<Note title="UI enabled in dev mode by default">

When you start the Vault server in dev mode, Vault UI is automatically enabled
at `http://127.0.0.1:8200/ui` and ready to use.

</Note>

## Policy requirements

@include 'ui/policy-requirements.mdx'

## Tutorial

Refer to the [UI quick start](/vault/tutorials/getting-started-ui) tutorials to
get familiar with Vault UI.
